Skip to content

feat(deps): upgrade upstream dependencies - #2778

Merged
fengmk2 merged 5 commits into
mainfrom
deps/upstream-update
Sep 22, 2026
Merged

fengmk2 merged 5 commits into
mainfrom
deps/upstream-update

Conversation

@voidzero-guard

Copy link
Copy Markdown
Contributor
  • Upgrade oxfmt to 0.70.0 and oxlint to 1.85.0 (pnpm catalog + lockfile).
  • Adjust vp migrate ESLint migration to resolve the @oxlint/migrate pin from the npm registry: @oxlint/migrate trails oxlint releases, so the exact bundled-oxlint pin can name a version not yet published. The newest published version not newer than the bundled Oxlint is used, falling back to the exact pin when the registry cannot be reached.
  • Add unit tests for the new version-resolution helper.

Dependency updates

Package From To
oxfmt 0.69.0 0.70.0
oxlint 1.84.0 1.85.0
Unchanged dependencies
  • rolldown: v1.2.9 (5b4746e)
  • vite: v8.3.0 (434e8e9)
  • vitest: 5.0.1
  • @vitest/browser: 5.0.1
  • @vitest/browser-playwright: 5.0.1
  • @vitest/browser-preview: 5.0.1
  • @vitest/mocker: 5.0.1
  • @vitest/pretty-format: 5.0.1
  • @vitest/snapshot: 5.0.1
  • @vitest/spy: 5.0.1
  • @vitest/utils: 5.0.1
  • tsdown: 0.23.0
  • @tsdown/css: 0.23.0
  • @tsdown/exe: 0.23.0
  • lightningcss: ^1.33.0
  • lint-staged: 17.5.1
  • @oxc-node/cli: 0.1.3
  • @oxc-node/core: 0.1.3
  • oxlint-tsgolint: 7.0.2002
  • @oxc-project/runtime: 0.151.0
  • @oxc-project/types: 0.151.0
  • oxc-minify: 0.151.0
  • oxc-parser: 0.151.0
  • oxc-transform: 0.151.0
  • VITEST_VERSION constant: 5.0.1
  • README vitest pins: 5.0.1

Code changes

  • packages/cli/src/migration/migrator/eslint.ts: add resolveOxlintMigrateVersion(), which queries the npm registry for published @oxlint/migrate versions and picks the greatest one that is not newer than the bundled oxlint version (falling back to the exact pin on registry error or non-OK response); the @oxlint/migrate dlx pin now uses this helper.
  • packages/cli/src/migration/__tests__/oxlint-plugin-dependency.spec.ts: add tests for resolveOxlintMigrateVersion() covering exact-pin match, trailing-registry fallback, ignoring newer published versions, network failure, error status, and no satisfying version.

Build status

  • sync-remote-and-build: success
  • build-upstream: success

- oxfmt: 0.69.0 -> 0.70.0
- oxlint: 1.84.0 -> 1.85.0

Code changes:
- packages/cli/src/migration/migrator/eslint.ts: add
  resolveOxlintMigrateVersion() to pin @oxlint/migrate to the newest
  published version not newer than the bundled oxlint, since
  @oxlint/migrate trails oxlint releases
- packages/cli/src/migration/__tests__/oxlint-plugin-dependency.spec.ts:
  add resolveOxlintMigrateVersion coverage
@voidzero-guard

Copy link
Copy Markdown
Contributor Author

✅ No upstream CLI help changes detected

Compared normalized --help output for the upstream CLIs mirrored by Vite+.

➖ Vite: no version update (8.3.0)

No version update was detected, so there is no CLI help diff.

➖ Vitest: no version update (5.0.1)

No version update was detected, so there is no CLI help diff.

✅ Oxlint: no CLI help changes (1.84.0 → 1.85.0)

The version was updated, but the normalized CLI help output has no differences.

✅ Oxfmt: no CLI help changes (0.69.0 → 0.70.0)

The version was updated, but the normalized CLI help output has no differences.

➖ tsdown: no version update (0.23.0)

No version update was detected, so there is no CLI help diff.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://deps-upstream-update-viteplus-dev.voidzero-docs.workers.dev (commit 6e7d6e6)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://576f4c4e-viteplus-dev.voidzero-docs.workers.dev 6e7d6e6 2026-09-22T03:30:16.860Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://b429a109-viteplus-dev.voidzero-docs.workers.dev 4ac93a5 2026-09-22T03:19:03.807Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://0b16ab38-viteplus-dev.voidzero-docs.workers.dev 4aae513 2026-09-22T02:43:25.291Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://492af853-viteplus-dev.voidzero-docs.workers.dev ee30467 2026-09-22T02:21:19.847Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://6cbbe271-viteplus-dev.voidzero-docs.workers.dev 329b5aa 2026-09-22T02:07:24.934Z Visit the dashboard ↗

@socket-security

socket-security Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​oxfmt@​0.69.0 ⏵ 0.70.0861008896 +2100

View full report

@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

CLI artifact sizes (6e7d6e6)

Final release artifacts built by the canonical build-upstream and build-windows-cli actions.
The dist rows use the Linux build. The core total excludes .node files to match the release artifact.

Artifact Format Base PR Change
packages/cli/dist Directory total 2.12 MiB 2.12 MiB +1.21 KiB (+0.06%)
packages/core/dist Directory total 3.95 MiB 3.95 MiB 0 B (0.00%)
Combined package dist Directory total 6.06 MiB 6.07 MiB +1.21 KiB (+0.02%)
vp (Linux x64) Binary 11.28 MiB 11.28 MiB 0 B (0.00%)
vp (Linux x64) gzip -9 4.88 MiB 4.88 MiB 0 B (0.00%)
NAPI (Linux x64) Binary 32.11 MiB 32.11 MiB 0 B (0.00%)
NAPI (Linux x64) gzip -9 12.73 MiB 12.73 MiB 0 B (0.00%)
vp (macOS ARM64) Binary 8.41 MiB 8.41 MiB 0 B (0.00%)
vp (macOS ARM64) gzip -9 4.26 MiB 4.26 MiB 0 B (0.00%)
NAPI (macOS ARM64) Binary 39.71 MiB 39.71 MiB 0 B (0.00%)
NAPI (macOS ARM64) gzip -9 17.04 MiB 17.04 MiB 0 B (0.00%)
vp (Windows x64) Binary 9.16 MiB 9.16 MiB 0 B (0.00%)
vp (Windows x64) gzip -9 4.00 MiB 4.00 MiB -1 B (-0.00%)
NAPI (Windows x64) Binary 27.07 MiB 27.07 MiB 0 B (0.00%)
NAPI (Windows x64) gzip -9 10.84 MiB 10.84 MiB -3 B (-0.00%)
Trampoline (Windows x64) Binary 13.50 KiB 13.50 KiB 0 B (0.00%)
Trampoline (Windows x64) gzip -9 7.09 KiB 7.09 KiB -2 B (-0.03%)
Installer (Windows x64) Binary 4.56 MiB 4.56 MiB 0 B (0.00%)
Installer (Windows x64) gzip -9 2.13 MiB 2.13 MiB -1 B (-0.00%)

@fengmk2 fengmk2 self-assigned this Sep 22, 2026
@fengmk2
fengmk2 merged commit 5790b12 into main Sep 22, 2026
120 checks passed
@fengmk2
fengmk2 deleted the deps/upstream-update branch September 22, 2026 03:42
fengmk2 added a commit that referenced this pull request Sep 22, 2026
…2780)

Vite+ now uses Vitest 5, and `vp migrate` helps Vitest 4 projects adopt
the new APIs and defaults. Standalone installs and upgrades now require
verified npm provenance for release binaries.

### Breaking Changes

#### Vitest 5

`vp test` and the public `vite-plus/test*` exports now use
`vitest@5.0.1`
([#2551](#2551)), by
@fengmk2.

| Area | Old | New |
| --- | --- | --- |
| Test runner | `vitest@4.1.11` | `vitest@5.0.1` |
| CLI Node.js range | `^20.19.0 \|\| ^22.18.0 \|\| >=24.11.0` |
`^22.18.0 \|\| ^24.11.0 \|\| >=26.0.0` |
| `vite-plus/test/runners` and `vite-plus/test/suite` | Vite+
compatibility exports | Use supported APIs from `vite-plus/test`; review
unsupported runner and expect plugins |
| `vite-plus/test/browser-webdriverio` | Bundled export | Use the
community `@vitest/browser-webdriverio` package |

Run `vp migrate` from the workspace root before you install the new
dependencies. The migrator updates supported config, source, benchmark,
command, and import changes. It reports manual work as `BLOCK` or
`REVIEW` items. See the [Vitest 5 migration
guide](https://viteplus.dev/guide/vitest-v5) for the full process.
Projects can stay on the prior release until their runtimes and tests
are ready.

#### `vp staged` runtime requirements

`vp staged` now uses `lint-staged@17.5.1`
([#2754](#2754)), by
@fengmk2.

| Requirement | Old | New |
| --- | --- | --- |
| Node.js for `vp staged` | The Vite+ CLI runtime range | `^22.22.1 \|\|
^24.11.0 \|\| >=26.0.0` |
| Git | No separate documented minimum | `>=2.32.0` |

Update Node.js and Git on developer machines and CI runners that execute
`vp staged` or its pre-commit hook. Other workflows do not use these
extra requirements.

### Highlights

- Standalone installers, `vp upgrade`, and `vp-setup.exe` now reject
release binaries without supported SLSA provenance
([#2440](#2440)), by
@kazupon.
- Installers now show progress and the exact shell activation command.
Download progress preserves earlier terminal output
([#2744](#2744),
[#2741](#2741)), by
@fengmk2.
- System-first runtime and package-manager shims now use a fallback
directory at the end of `PATH`. Setup restores missing package-manager
preferences
([#2758](#2758),
[#2763](#2763)), by
@liangmiQwQ and @fengmk2.
- `vp run` now finishes when background processes remain. Large file
traces run without caching instead of killing the task
([#2767](#2767),
[vite-task#675](voidzero-dev/vite-task#675)), by
@wan9chi.

### Features

- `vp add` now supports shared install options such as `--offline`,
`--frozen-lockfile`, and `--lockfile-only`
([#2722](#2722)), by
@jong-kyung.
- `vp pm patch` and `vp pm patch-commit` now use the native commands in
npm 12 and later
([#2736](#2736)), by
@jong-kyung.
- `vp rebuild` now supports Yarn Berry and forwards package names and
extra arguments
([#2761](#2761)), by
@jong-kyung.
- The bundled tools update `oxlint` `1.83.0` -> `1.85.0`,
`oxlint-tsgolint` `7.0.2001` -> `7.0.2002`, and `oxfmt` `0.68.0` ->
`0.70.0` ([#2745](#2745),
[#2773](#2773),
[#2778](#2778)), by
@voidzero-guard[bot]. These versions can flag or format code that passed
before. Run `vp fmt` after upgrading if CI runs `vp check`.

### Fixes & Enhancements

- `oxlint` and `oxfmt` no longer expose bin wrappers that conflict with
upstream packages. Editors must use `vp lint --lsp`, `vp fmt --lsp`, or
`vp fmt --stdin-filepath`
([#2672](#2672)), by
@fengmk2.
- `vp create vite:generator` now replaces catalog references for package
managers that do not support catalogs
([#2720](#2720)), by
@SaKaNa-Y.
- Unpinned npm projects now use the npm version bundled with the
selected Node.js runtime. The same policy works during migration
([#2742](#2742),
[#2748](#2748)), by
@liangmiQwQ.
- The CLI now loads its local versions module through a file URL,
including on Windows paths
([#2749](#2749)), by
@YanChenBai.
- Package-manager commands now use pnpm when the project has no detected
package manager
([#2750](#2750)), by
@liangmiQwQ.
- `vp migrate` now removes unused `@oxlint/plugins` dependencies after
it rewrites plugin imports
([#2751](#2751)), by
@fengmk2.
- `vp update --no-save` now warns that Yarn Classic and Yarn Berry do
not support the option
([#2762](#2762)), by
@jong-kyung.
- `vp migrate` now explains its `tsdown@0.23` compatibility settings and
links to removal guidance
([#2769](#2769)), by
@fengmk2.
- Environment setup now installs and diagnoses the official `pn` and
`pnx` aliases for pnpm
([#2770](#2770)), by
@iruoy.
- Cached tasks now receive GitHub Actions OIDC variables, so npm Trusted
Publishing works through `vp run`
([vite-task#691](voidzero-dev/vite-task#691)),
by @naokihaba.
- Automatic task input tracking now records file access from signal
handlers
([vite-task#687](voidzero-dev/vite-task#687)),
by @wan9chi.

### Refactor

- `vp lint`, `vp fmt`, and `vp check` now use native config discovery.
Package commands keep matching workspace-root settings, while explicit
config flags take precedence
([#2731](#2731)), by
@fengmk2.

### Chore

- Generated workflows and `vp migrate` now use `setup-vp@v1.21.1`,
including its installation fixes
([#2760](#2760),
[#2772](#2772)), by
@renovate[bot] and @fengmk2.

### Bundled Versions

| Tool | Version | Source |
| --- | --- | --- |
| vite | `8.3.0` |
[`434e8e9`](vitejs/vite@434e8e9)
|
| rolldown | `1.2.9` |
[`5b4746e`](rolldown/rolldown@5b4746e)
|
| tsdown | `0.23.0` | [npm](https://npmx.dev/package/tsdown/v/0.23.0) |
| vitest | `5.0.1` | [npm](https://npmx.dev/package/vitest/v/5.0.1) |
| oxlint | `1.85.0` | [npm](https://npmx.dev/package/oxlint/v/1.85.0) |
| oxlint-tsgolint | `7.0.2002` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2002) |
| oxfmt | `0.70.0` | [npm](https://npmx.dev/package/oxfmt/v/0.70.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@YanChenBai, @iruoy

**Full Changelog**:
v0.3.3...v1.0.0-rc.0

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK (fengmk2) <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant